56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-23664 | HIGH 7.5 | microsoft azure_iot_explorer Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2022-29146 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2022-29144 | HIGH 7.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2022-21847 | MED 6.5 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 1.0% | — |
| CVE-2025-21383 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 1.0% | — |
| CVE-2023-35635 | MED 5.5 | microsoft windows_11_22h2 Windows Kernel Denial of Service Vulnerability | 1.0% | — |
| CVE-2020-17038 | HIGH 7.8 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2020-0998 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>In a local attack scenario, | 1.0% | — |
| CVE-2020-0870 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Shell infrastructure component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>To exploit this vulnera | 1.0% | — |
| CVE-2020-0838 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when NTFS improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>To exploit the vulnerability, an attacker would first have to log | 1.0% | — |
| CVE-2020-0782 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Cryptographic Catalog Services improperly handle objects in memory. An attacker who successfully exploited this vulnerability could modify the cryptographic catalog.</p> <p>To exploit this vuln | 1.0% | — |
| CVE-2026-57982 | MED 6.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-54116 | MED 6.5 | microsoft sql_server_2025 Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-50468 | MED 6.5 | microsoft sql_server_2025 Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2023-36020 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 1.0% | — |
| CVE-2022-30138 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-21552 | MED 5.2 | microsoft windows_10 Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability. A local authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass the restricted environment and | 1.0% | — |
| CVE-2025-29840 | HIGH 8.8 | microsoft windows_10_1507 Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2023-36393 | HIGH 7.8 | microsoft windows_10_1507 Windows User Interface Application Core Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2022-41116 | MED 5.9 | microsoft windows_7 Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability | 1.0% | — |
| CVE-2022-41090 | MED 5.9 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability | 1.0% | — |
| CVE-2024-26257 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-21712 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2026-58291 | MED 6.1 | microsoft edge_chromium Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2025-59502 | HIGH 7.5 | microsoft windows_10_1809 Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network. | 1.0% | — |